中文

对抗鲁棒性与架构组件的交互:图像块、卷积与注意力

计算机视觉与模式识别 2022-09-16 v1 机器学习

摘要

近年来,用于图像分类的新颖架构组件得到发展,始于 transformer 中使用的注意力和图像块。尽管先前工作已分析架构组件的某些方面对对抗攻击鲁棒性的影响,特别是针对视觉 transformer,但对主要因素的理解仍然有限。我们比较了具有不同架构的多个(非)鲁棒分类器,并研究其性质,包括对抗训练对所学特征可解释性以及针对未见威胁模型的鲁棒性的影响。从 ResNet 到 ConvNeXt 的消融揭示了对导致几乎高 10%10\%\ell_\infty-鲁棒性的关键架构改变。

关键词

引用

@article{arxiv.2209.06953,
  title  = {On the interplay of adversarial robustness and architecture components: patches, convolution and attention},
  author = {Francesco Croce and Matthias Hein},
  journal= {arXiv preprint arXiv:2209.06953},
  year   = {2022}
}

备注

Presented at the "New Frontiers in Adversarial Machine Learning" Workshop at ICML 2022